---
title: "Section 9: Processing of personal data of children"
url: https://dpdp.myndsolution.com/wiki/act/section-9-processing-of-personal-data-of-children/
description: "Section 9 of the Digital Personal Data Protection Act, 2023 (Processing of personal data of children). Official text verbatim, comes into force on 13 may…"
kind: act-section
updated: 2026-09-09
official_source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/act/section-9-processing-of-personal-data-of-children/
---
# Section 9: Processing of personal data of children

*The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Chapter II: OBLIGATIONS OF DATA FIDUCIARY. Comes into force on 13 May 2027.*

## Official text

- **(1)** The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian obtain verifiable consent of the parent of such child or the lawful guardian, as the case may be, in such manner as may be prescribed.

**Explanation.—** For the purpose of this sub-section, the expression “consent of the parent” includes the consent of lawful guardian, wherever applicable.

- **(2)** A Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child.

- **(3)** A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

- **(4)** The provisions of sub-sections (1) and (3) shall not be applicable to processing of personal data of a child by such classes of Data Fiduciaries or for such purposes, and subject to such conditions, as may be prescribed.

- **(5)** The Central Government may, if satisfied that a Data Fiduciary has ensured that its processing of personal data of children is done in a manner that is verifiably safe, notify for such processing by such Data Fiduciary the age above which that Data Fiduciary shall be exempt from the applicability of all or any of the obligations under sub-sections (1) and (3) in respect of processing by that Data Fiduciary as the notification may specify.


## Rules made under this section

- [Rule 10: Verifiable consent for processing of personal data of child](https://dpdp.myndsolution.com/wiki/rules/rule-10-verifiable-consent-for-processing-of-personal-data-of-child/)
- [Rule 11: Verifiable consent for processing of personal data of person with disability who has lawful guardian](https://dpdp.myndsolution.com/wiki/rules/rule-11-verifiable-consent-for-processing-of-personal-data-of-person/)
- [Rule 12: Exemptions from certain obligations applicable to processing of personal data of child](https://dpdp.myndsolution.com/wiki/rules/rule-12-exemptions-from-certain-obligations-applicable-to-processing/)

## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

Before a Data Fiduciary (an entity that determines the purpose and means of processing data) processes the personal data of a child, it must obtain verifiable consent from the child's parent. This rule also applies to a person with a disability who has a lawful guardian, requiring the guardian's verifiable consent. The exact manner of verifying this consent will be prescribed in future rules.

The law places strict limits on how children's data can be used. A Data Fiduciary is prohibited from processing personal data in any way that is likely to cause a detrimental effect on a child's well-being. Additionally, a Data Fiduciary cannot track children, monitor their behavior, or direct targeted advertising at them.

There are exceptions to these strict rules. The government may prescribe certain classes of Data Fiduciaries, or specific purposes, that are exempt from the parental consent and tracking restrictions. Furthermore, if the Central Government is satisfied that a particular Data Fiduciary processes children's data in a verifiably safe manner, it can issue a notification. This notification can specify an age above which that specific Data Fiduciary is exempt from the parental consent and tracking rules.

### Key points

- A Data Fiduciary must obtain verifiable consent from a parent or lawful guardian before processing the personal data of a child or a person with a disability who has a lawful guardian (1).
- A Data Fiduciary cannot process personal data in a way that is likely to cause a detrimental effect on a child's well-being (2).
- Tracking, behavioral monitoring, and targeted advertising directed at children are strictly prohibited (3).
- The government may prescribe exemptions from the consent and tracking rules for certain classes of Data Fiduciaries or specific purposes (4).
- The Central Government can lower the age limit for the consent and tracking rules for a specific Data Fiduciary if it is satisfied their processing is verifiably safe (5).

### Common misreadings

- Assuming the ban on tracking and targeted advertising has no exceptions; the government can prescribe exemptions for certain Data Fiduciaries or purposes.
- Believing the age limit for parental consent is entirely fixed; the Central Government can notify a lower age threshold for specific Data Fiduciaries that operate in a verifiably safe manner.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

---
Cite as: Digital Personal Data Protection Act, 2023, s. 9. Official source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
